Multivan ื•ื ื™ืชื•ื‘ ืขืœ Mikrotik RouterOS

ืžื‘ื•ื

ืงื‘ืœืช ื”ืžืืžืจ, ื‘ื ื•ืกืฃ ืœื”ื‘ืœ, ื ื‘ืข ืžื”ืชื“ื™ืจื•ืช ื”ืžื“ื›ืืช ืฉืœ ืฉืืœื•ืช ื‘ื ื•ืฉื ื–ื” ื‘ืงื‘ื•ืฆื•ืช ื”ืคืจื•ืคื™ืœ ืฉืœ ืงื”ื™ืœืช ื”ื˜ืœื’ืจื ื“ื•ื‘ืจื™ ื”ืจื•ืกื™ืช. ื”ืžืืžืจ ืžื™ื•ืขื“ ืœืžื ื”ืœื™ Mikrotik RouterOS ืžืชื—ื™ืœื™ื (ืœื”ืœืŸ ROS). ื”ื•ื ืขื•ืกืง ืจืง ื‘ืžื•ืœื˜ื™ื•ื•ืืŸ, ื‘ื“ื’ืฉ ืขืœ ื ื™ืชื•ื‘. ื›ื‘ื•ื ื•ืก, ื™ืฉื ืŸ ื”ื’ื“ืจื•ืช ืžืกืคื™ืงื•ืช ื‘ืžื™ื ื™ืžื•ื ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืคืขื•ืœื” ื‘ื˜ื•ื—ื” ื•ื ื•ื—ื”. ืžื™ ืฉืžื—ืคืฉ ื—ืฉื™ืคื” ืฉืœ ื ื•ืฉืื™ ืชื•ืจื™ื, ืื™ื–ื•ืŸ ืขื•ืžืกื™ื, vlans, ื’ืฉืจื™ื, ื ื™ืชื•ื— ืขืžื•ืง ืจื‘-ืฉืœื‘ื™ ืฉืœ ืžืฆื‘ ื”ืขืจื•ืฅ ื•ื›ื“ื•ืžื” - ืขืœื•ืœ ืฉืœื ืœื‘ื–ื‘ื– ื–ืžืŸ ื•ืžืืžืฅ ื‘ืงืจื™ืื”.

ื ืชื•ื ื™ื ื’ื•ืœืžื™ื™ื

ื›ื ื‘ื“ืง, ื ื‘ื—ืจ ื ืชื‘ Mikrotik ื‘ืขืœ ื—ืžืฉ ื™ืฆื™ืื•ืช ืขื ื’ืจืกืช ROS 6.45.3. ื”ื•ื ื™ื ืชื‘ ืชืขื‘ื•ืจื” ื‘ื™ืŸ ืฉืชื™ ืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช (LAN1 ื•-LAN2) ืœืฉืœื•ืฉื” ืกืคืงื™ื (ISP1, ISP2, ISP3). ืœืขืจื•ืฅ ืœ-ISP1 ื™ืฉ ื›ืชื•ื‘ืช ืกื˜ื˜ื™ืช "ืืคื•ืจื”", ISP2 - "ืœื‘ื ื”", ื”ืžืชืงื‘ืœืช ื‘ืืžืฆืขื•ืช DHCP, ISP3 - "ืœื‘ื ื”" ืขื ื”ืจืฉืืช PPPoE. ืชืจืฉื™ื ื”ื—ื™ื‘ื•ืจ ืžื•ืฆื’ ื‘ืื™ื•ืจ:

Multivan ื•ื ื™ืชื•ื‘ ืขืœ Mikrotik RouterOS

ื”ืžืฉื™ืžื” ื”ื™ื ืœื”ื’ื“ื™ืจ ืืช ื ืชื‘ MTK ื‘ื”ืชื‘ืกืก ืขืœ ื”ืกื›ื™ืžื” ื›ืš:

  1. ืกืคืง ืžืขื‘ืจ ืื•ื˜ื•ืžื˜ื™ ืœืกืคืง ื’ื™ื‘ื•ื™. ื”ืกืคืง ื”ืจืืฉื™ ื”ื•ื ISP2, ื”ืขืชื•ื“ื” ื”ืจืืฉื•ื ื” ื”ื™ื ISP1, ื”ืขืชื•ื“ื” ื”ืฉื ื™ื™ื” ื”ื™ื ISP3.
  2. ืืจื’ืŸ ื’ื™ืฉื” ืœืจืฉืช LAN1 ืœืื™ื ื˜ืจื ื˜ ืจืง ื“ืจืš ISP1.
  3. ืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœื ืชื‘ ืชืขื‘ื•ืจื” ืžืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช ืœืื™ื ื˜ืจื ื˜ ื“ืจืš ื”ืกืคืง ื”ื ื‘ื—ืจ ื‘ื”ืชื‘ืกืก ืขืœ ืจืฉื™ืžืช ื”ื›ืชื•ื‘ื•ืช.
  4. ืœืกืคืง ืืคืฉืจื•ืช ืœืคืจืกื•ื ืฉื™ืจื•ืชื™ื ืžื”ืจืฉืช ื”ืžืงื•ืžื™ืช ืœืื™ื ื˜ืจื ื˜ (DSTNAT)
  5. ื”ื’ื“ืจ ืžืกื ืŸ ื—ื•ืžืช ืืฉ ื›ื“ื™ ืœืกืคืง ืื‘ื˜ื—ื” ืžื™ื ื™ืžืœื™ืช ืžืกืคืงืช ืžื”ืื™ื ื˜ืจื ื˜.
  6. ื”ื ืชื‘ ื™ื›ื•ืœ ืœื”ื ืคื™ืง ืชืขื‘ื•ืจื” ืžืฉืœื• ื“ืจืš ื›ืœ ืื—ื“ ืžืฉืœื•ืฉืช ื”ืกืคืงื™ื, ื‘ื”ืชืื ืœื›ืชื•ื‘ืช ื”ืžืงื•ืจ ืฉื ื‘ื—ืจื”.
  7. ื•ื“ื ืฉืžื ื•ืช ื”ืชื’ื•ื‘ื” ืžื ื•ืชื‘ื•ืช ืœืขืจื•ืฅ ืฉืžืžื ื• ื”ื’ื™ืขื• (ื›ื•ืœืœ LAN).

REMARK. ืื ื• ื ื’ื“ื™ืจ ืืช ื”ื ืชื‘ "ืžืืคืก" ืขืœ ืžื ืช ืœื”ื‘ื˜ื™ื— ื”ื™ืขื“ืจ ื”ืคืชืขื•ืช ื‘ืชืฆื•ืจื•ืช ื”ื”ืชื—ืœืชื™ื•ืช "ืžื—ื•ืฅ ืœืงื•ืคืกื”" ื”ืžืฉืชื ื•ืช ืžื’ืจืกื” ืœื’ืจืกื”. Winbox ื ื‘ื—ืจื” ื›ื›ืœื™ ืชืฆื•ืจื”, ืฉื‘ื• ื”ืฉื™ื ื•ื™ื™ื ื™ื•ืฆื’ื• ื•ื™ื–ื•ืืœื™ืช. ื”ื”ื’ื“ืจื•ืช ืขืฆืžืŸ ื™ื•ื’ื“ืจื• ืขืœ ื™ื“ื™ ืคืงื•ื“ื•ืช ื‘ืžืกื•ืฃ Winbox. ื”ื—ื™ื‘ื•ืจ ื”ืคื™ื–ื™ ืœืชืฆื•ืจื” ื ืขืฉื” ืขืœ ื™ื“ื™ ื—ื™ื‘ื•ืจ ื™ืฉื™ืจ ืœืžืžืฉืง Ether5.

ืงืฆืช ื”ื™ื’ื™ื•ืŸ ืœื’ื‘ื™ ืžื” ื–ื” ืžื•ืœื˜ื™ื•ื•ืืŸ, ื”ืื ื–ื• ื‘ืขื™ื” ืื• ืฉืื ืฉื™ื ื—ื›ืžื™ื ืขืจืžื•ืžื™ื™ื ืกื‘ื™ื‘ ืืจื™ื’ืช ืจืฉืชื•ืช ืงื•ื ืกืคื™ืจืฆื™ื”

ืžื ื”ืœ ืกืงืจืŸ ื•ืงืฉื•ื‘, ืฉืžืงื™ื ืชื•ื›ื ื™ืช ื›ื–ื• ืื• ื“ื•ืžื” ื‘ืขืฆืžื•, ืคืชืื•ื ืžื‘ื™ืŸ ืฉื–ื” ื›ื‘ืจ ืขื•ื‘ื“ ื›ืจื’ื™ืœ. ื›ืŸ, ื›ืŸ, ืœืœื ื˜ื‘ืœืื•ืช ื”ื ื™ืชื•ื‘ ื”ืžื•ืชืืžื•ืช ืื™ืฉื™ืช ื•ื›ืœืœื™ ืžืกืœื•ืœ ืื—ืจื™ื, ืฉืจื•ื‘ ื”ืžืืžืจื™ื ื‘ื ื•ืฉื ื–ื” ืžืœืื™ื ื‘ื”ื. ื‘ื•ื ื ื‘ื“ื•ืง?

ื”ืื ื ื•ื›ืœ ืœื”ื’ื“ื™ืจ ื›ืชื•ื‘ืช ื‘ืžืžืฉืงื™ื ื•ืฉืขืจ ื‘ืจื™ืจืช ืžื—ื“ืœ? ื›ืŸ:

ื‘-ISP1, ื”ื›ืชื•ื‘ืช ื•ื”ืฉืขืจ ื ืจืฉืžื• ืขื ืžืจื—ืง=2 ะธ check-gateway=ping.
ื‘-ISP2, ื”ื’ื“ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ืœืงื•ื— dhcp - ื‘ื”ืชืื, ื”ืžืจื—ืง ื™ื”ื™ื” ืฉื•ื•ื” ืœืื—ื“.
ื‘-ISP3 ื‘ื”ื’ื“ืจื•ืช ืœืงื•ื— pppoe ื›ืืฉืจ add-default-route=yes ืœึธืฉื‚ึดื™ื default-route-distance=3.

ืืœ ืชืฉื›ื— ืœืจืฉื•ื NAT ื‘ื™ืฆื™ืื”:

/ip firewall nat add action=masquerade chain=srcnat out-interface-list=WAN

ื›ืชื•ืฆืื” ืžื›ืš, ืžืฉืชืžืฉื™ื ื‘ืืชืจื™ื ืžืงื•ืžื™ื™ื ื ื”ื ื™ื ืœื”ื•ืจื™ื“ ื—ืชื•ืœื™ื ื“ืจืš ืกืคืง ISP2 ื”ืจืืฉื™ ื•ื™ืฉื ื” ื”ื–ืžื ืช ืขืจื•ืฆื™ื ื‘ืืžืฆืขื•ืช ื”ืžื ื’ื ื•ืŸ ืœื‘ื“ื•ืง ืฉืขืจ ืจืื” ื”ืขืจื” 1

ื ืงื•ื“ื” 1 ืฉืœ ื”ืžืฉื™ืžื” ืžื™ื•ืฉืžืช. ืื™ืคื” ื”ืžื•ืœื˜ื™ื•ื•ืืŸ ืขื ื”ืกื™ืžื ื™ื ืฉืœื•? ืœืโ€ฆ

ื ื•ืกืฃ. ืขืœื™ืš ืœืฉื—ืจืจ ืœืงื•ื—ื•ืช ืกืคืฆื™ืคื™ื™ื ืžื”-LAN ื“ืจืš ISP1:

/ip ื—ื•ืžืช ืืฉ mangle add action=route chain=prerouting dst-address-list=!BOGONS
passthrough=yes route-dst=100.66.66.1 src-address-list=Via_ISP1
/ip ื—ื•ืžืช ืืฉ mangle add action=route chain=prerouting dst-address-list=!BOGONS
passthrough=no route-dst=100.66.66.1 src-address=192.168.88.0/24

ืคืจื™ื˜ื™ื 2 ื•-3 ืฉืœ ื”ืžืฉื™ืžื” ื™ื•ืฉืžื•. ืชื•ื•ื™ื•ืช, ื—ื•ืชืžื•ืช, ื—ื•ืงื™ ืžืกืœื•ืœ, ืื™ืคื” ืืชื”?!

ืฆืจื™ืš ืœืชืช ื’ื™ืฉื” ืœืฉืจืช OpenVPN ื”ืžื•ืขื“ืฃ ืขืœื™ืš ืขื ื”ื›ืชื•ื‘ืช 172.17.17.17 ืขื‘ื•ืจ ืœืงื•ื—ื•ืช ืžื”ืื™ื ื˜ืจื ื˜? ืื ื:

/ip cloud set ddns-enabled=yes

ื‘ืชื•ืจ ืขืžื™ืช, ืื ื• ื ื•ืชื ื™ื ืœืœืงื•ื— ืืช ืชื•ืฆืืช ื”ืคืœื˜: ": ืœืฉื™ื [ืขื ืŸ IP ืงื‘ืœ dns-name]"

ืื ื• ืจื•ืฉืžื™ื ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช ืžื”ืื™ื ื˜ืจื ื˜:

/ip ื—ื•ืžืช ืืฉ nat add action=dst-nat chain=dstnat dst-port=1194
in-interface-list=ืคืจื•ื˜ื•ืงื•ืœ WAN=udp to-addresses=172.17.17.17

ืคืจื™ื˜ 4 ืžื•ื›ืŸ.

ื”ืงืžื ื• ื—ื•ืžืช ืืฉ ื•ืื‘ื˜ื—ื” ื ื•ืกืคืช ืœื ืงื•ื“ื” 5, ื‘ืžืงื‘ื™ืœ ืื ื• ืฉืžื—ื™ื ืฉื”ื›ืœ ื›ื‘ืจ ืขื•ื‘ื“ ืœืžืฉืชืžืฉื™ื ื•ืžื’ื™ืขื™ื ืœืžื™ื›ืœ ืขื ืžืฉืงื” ืื”ื•ื‘...
ื! ืžื ื”ืจื•ืช ื ืฉื›ื—ื•ืช.

l2tp-client, ืฉื”ื•ื’ื“ืจ ืขืœ ื™ื“ื™ ืžืืžืจ ื’ื•ื’ืœ, ืขืœื” ืœ-VDS ื”ื”ื•ืœื ื“ื™ ื”ืžื•ืขื“ืฃ ืขืœื™ืš? ื›ืŸ.
ืฉืจืช l2tp ืขื IPsec ืขืœื” ื•ืœืงื•ื—ื•ืช ืœืคื™ ืฉื DNS ืž-IP Cloud (ืจืื” ืœืžืขืœื”.) ื ืื—ื–ื™ื? ื›ืŸ.
ื ืฉืขื ื™ื ืœืื—ื•ืจ ืขืœ ื”ื›ื™ืกื, ืœื•ื’ืžื™ื ืžืฉืงื”, ืื ื• ืฉื•ืงืœื™ื ื‘ืขืฆืœืชื™ื™ื ืืช ื ืงื•ื“ื•ืช 6 ื•-7 ืฉืœ ื”ืžืฉื™ืžื”. ืื ื—ื ื• ื—ื•ืฉื‘ื™ื - ื”ืื ืื ื—ื ื• ืฆืจื™ื›ื™ื ืืช ื–ื”? ื‘ื›ืœ ื–ืืช, ื–ื” ืขื•ื‘ื“ ื›ื›ื” (ื’) ... ืื– ืื ื–ื” ืขื“ื™ื™ืŸ ืœื ื ื—ื•ืฅ, ืื– ื–ื”ื•. ืžื•ืœื˜ื™ื•ื•ืืŸ ืžื™ื•ืฉื.

ืžื” ื–ื” ืžื•ืœื˜ื™ื•ื•ืืŸ? ื–ื”ื• ื—ื™ื‘ื•ืจ ืฉืœ ืžืกืคืจ ืขืจื•ืฆื™ ืื™ื ื˜ืจื ื˜ ืœื ืชื‘ ืื—ื“.

ืืชื” ืœื ืฆืจื™ืš ืœืงืจื•ื ืืช ื”ืžืืžืจ ื™ื•ืชืจ, ื›ื™ ืžื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื ืžืœื‘ื“ ื”ืฆื’ื” ืฉืœ ื™ืฉื™ืžื•ืช ืžืคื•ืงืคืงืช?

ืœืžื™ ืฉื ืฉืืจ, ืฉืžืชืขื ื™ื™ืŸ ื‘ื ืงื•ื“ื•ืช 6 ื•-7 ืฉืœ ื”ืžืฉื™ืžื”, ื•ื’ื ืžืจื’ื™ืฉ ื’ืจื“ ืฉืœ ืคืจืคืงืฆื™ื•ื ื™ื–ื, ืื ื—ื ื• ืฆื•ืœืœื™ื ื™ื•ืชืจ ืœืขื•ืžืง.

ื”ืžืฉื™ืžื” ื”ื—ืฉื•ื‘ื” ื‘ื™ื•ืชืจ ืฉืœ ื”ื˜ืžืขืช ืžื•ืœื˜ื™ื•ื•ืืŸ ื”ื™ื ื ื™ืชื•ื‘ ืชื ื•ืขื” ื ื›ื•ืŸ. ื›ืœื•ืžืจ: ื‘ืœื™ ืงืฉืจ ืœืื™ื–ื” (ืื• ืื™ื–ื”) ืจืื”. ื”ืขืจื” 3 ืขืจื•ืฆื™ ืกืคืง ืฉื™ืจื•ืชื™ ื”ืื™ื ื˜ืจื ื˜ ืžืกืชื›ืœื™ื ืขืœ ืžืกืœื•ืœ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื‘ื ืชื‘ ืฉืœื ื•, ื”ื•ื ืืžื•ืจ ืœื”ื—ื–ื™ืจ ืชื’ื•ื‘ื” ืœืขืจื•ืฅ ื”ืžื“ื•ื™ืง ืžืžื ื• ื”ื’ื™ืขื” ื”ื—ื‘ื™ืœื”. ื”ืžืฉื™ืžื” ื‘ืจื•ืจื”. ืื™ืคื” ื”ื‘ืขื™ื”? ืื›ืŸ, ื‘ืจืฉืช ืžืงื•ืžื™ืช ืคืฉื•ื˜ื” ื”ืžืฉื™ืžื” ื–ื”ื”, ืื‘ืœ ืืฃ ืื—ื“ ืœื ืžืชืขืกืง ื‘ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช ื•ืœื ืžืจื’ื™ืฉ ืฆืจื•ืช. ื”ื”ื‘ื“ืœ ื”ื•ื ืฉื›ืœ ืฆื•ืžืช ื ื™ืชืŸ ืœื ื™ืชื•ื‘ ื‘ืื™ื ื˜ืจื ื˜ ื ื’ื™ืฉ ื“ืจืš ื›ืœ ืื—ื“ ืžื”ืขืจื•ืฆื™ื ืฉืœื ื•, ื•ืœื ื“ืจืš ืื—ื“ ืกืคืฆื™ืคื™ ืœืžื”ื“ืจื™ืŸ, ื›ืžื• ื‘ืจืฉืช LAN ืคืฉื•ื˜ื”. ื•ื”"ื‘ืขื™ื”" ื”ื™ื ืฉืื ื”ื’ื™ืขื” ืืœื™ื ื• ื‘ืงืฉื” ืœื›ืชื•ื‘ืช ื”-IP ืฉืœ ISP3, ืื– ื‘ืžืงืจื” ืฉืœื ื• ื”ืชืฉื•ื‘ื” ืชืขื‘ื•ืจ ื‘ืขืจื•ืฅ ISP2, ืฉื›ืŸ ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืžื•ืคื ื” ืœืฉื. ืžืฉืื™ืจ ื•ื™ื•ืกืจ ืขืœ ื™ื“ื™ ื”ืกืคืง ื›ืฉื’ื•ื™. ื”ื‘ืขื™ื” ื–ื•ื”ืชื”. ืื™ืš ืœืคืชื•ืจ ืืช ื–ื”?

ื”ืคืชืจื•ืŸ ืžื—ื•ืœืง ืœืฉืœื•ืฉื” ืฉืœื‘ื™ื:

  1. ื”ื’ื“ืจื” ืžืจืืฉ. ื‘ืฉืœื‘ ื–ื” ื™ื•ื’ื“ืจื• ื”ื”ื’ื“ืจื•ืช ื”ื‘ืกื™ืกื™ื•ืช ืฉืœ ื”ื ืชื‘: ืจืฉืช ืžืงื•ืžื™ืช, ื—ื•ืžืช ืืฉ, ืจืฉื™ืžื•ืช ื›ืชื•ื‘ื•ืช, NAT ืกื™ื›ืช ืจืืฉ ื•ื›ื•'.
  2. ืžื•ืœื˜ื™ื•ื•ืืŸ. ื‘ืฉืœื‘ ื–ื” ื™ืกื•ืžื ื• ื”ื—ื™ื‘ื•ืจื™ื ื”ื“ืจื•ืฉื™ื ื•ื™ืžื•ื™ื ื• ืœื˜ื‘ืœืื•ืช ื ื™ืชื•ื‘.
  3. ืžืชื—ื‘ืจ ืœืกืคืง ืื™ื ื˜ืจื ื˜. ื‘ืฉืœื‘ ื–ื” ื™ื•ื’ื“ืจื• ื”ืžืžืฉืงื™ื ื”ืžืกืคืงื™ื ื—ื™ื‘ื•ืจ ืœืื™ื ื˜ืจื ื˜, ื™ื•ืคืขืœ ื ื™ืชื•ื‘ ื•ืžื ื’ื ื•ืŸ ื”ื–ืžื ืช ืขืจื•ืฅ ื”ืื™ื ื˜ืจื ื˜.

1. ื”ื’ื“ืจื” ืžืจืืฉ

1.1. ืื ื• ืžื ืงื™ื ืืช ืชืฆื•ืจืช ื”ื ืชื‘ ืขื ื”ืคืงื•ื“ื”:

/system reset-configuration skip-backup=yes no-defaults=yes

ืžืกื›ื™ื ืขื "ืžึฐืกื•ึผื›ึผึธืŸ! ืœืืคืก ื‘ื›ืœ ื–ืืช? [ื™/N]:" ื•ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ, ืื ื• ืžืชื—ื‘ืจื™ื ืœ- Winbox ื“ืจืš MAC. ื‘ืฉืœื‘ ื–ื”, ื”ืชืฆื•ืจื” ื•ื‘ืกื™ืก ื”ืžืฉืชืžืฉื™ื ืžื ื•ืงื™ื.

1.2. ืฆื•ืจ ืžืฉืชืžืฉ ื—ื“ืฉ:

/user add group=full name=knight password=ultrasecret comment=โ€Not horseโ€

ื”ื™ื›ื ืก ืชื—ืชื™ื• ื•ืžื—ืง ืืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ:

/user remove admin

REMARK. ื”ื”ืกืจื” ื•ืื™ ื”ืฉื‘ืชื” ืฉืœ ืžืฉืชืžืฉ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื™ื ืฉื”ืžื—ื‘ืจ ืžื—ืฉื™ื‘ ืœื‘ื˜ื•ื— ื™ื•ืชืจ ื•ืžืžืœื™ืฅ ืœืฉื™ืžื•ืฉ.

1.3. ืื ื• ื™ื•ืฆืจื™ื ืจืฉื™ืžื•ืช ืžืžืฉืงื™ื ื‘ืกื™ืกื™ื•ืช ืœื ื•ื—ื•ืช ื”ื”ืคืขืœื” ื‘ื—ื•ืžืช ืืฉ, ื”ื’ื“ืจื•ืช ื’ื™ืœื•ื™ ื•ืฉืจืชื™ MAC ืื—ืจื™ื:

/interface list add name=WAN comment="For Internet"
/interface list add name=LAN comment="For Local Area"

ืžืžืฉืงื™ ื—ืชื™ืžื” ืขื ื”ืขืจื•ืช

/interface ethernet set ether1 comment="to ISP1"
/interface ethernet set ether2 comment="to ISP2"
/interface ethernet set ether3 comment="to ISP3"
/interface ethernet set ether4 comment="to LAN1"
/interface ethernet set ether5 comment="to LAN2"

ื•ืžืœื ืืช ืจืฉื™ืžื•ืช ื”ืžืžืฉืง:

/interface list member add interface=ether1 list=WAN comment=ISP1
/interface list member add interface=ether2 list=WAN comment=ISP2 
/interface list member add interface=ether3 list=WAN comment="to ISP3"
/interface list member add interface=ether4 list=LAN  comment="LAN1"
/interface list member add interface=ether5 list=LAN  comment="LAN2"

REMARK. ื›ืชื™ื‘ืช ื”ืขืจื•ืช ืžื•ื‘ื ื•ืช ืฉื•ื•ื” ืืช ื”ื–ืžืŸ ื”ืžื•ืฉืงืข ื‘ื–ื”, ื‘ื ื•ืกืฃ ื–ื” ืžืงืœ ืžืื•ื“ ืขืœ ืคืชืจื•ืŸ ื‘ืขื™ื•ืช ื•ื”ื‘ื ืช ื”ืชืฆื•ืจื”.

ื”ืžื—ื‘ืจ ืจื•ืื” ืฆื•ืจืš, ืžื˜ืขืžื™ ืื‘ื˜ื—ื”, ืœื”ื•ืกื™ืฃ ืืช ืžืžืฉืง ether3 ืœืจืฉื™ืžืช ืžืžืฉืงื™ "WAN", ืœืžืจื•ืช ื”ืขื•ื‘ื“ื” ืฉืคืจื•ื˜ื•ืงื•ืœ ื”-ip ืœื ื™ืขื‘ื•ืจ ื“ืจื›ื•.

ืืœ ืชืฉื›ื— ืฉืื—ืจื™ ืฉืžืžืฉืง PPP ื™ื•ืขืœื” ืขืœ ether3, ื™ื”ื™ื” ืฆื•ืจืš ืœื”ื•ืกื™ืฃ ืื•ืชื• ื’ื ืœืจืฉื™ืžืช ื”ืžืžืฉืงื™ื "WAN"

1.4. ืื ื• ืžืกืชื™ืจื™ื ืืช ื”ื ืชื‘ ืžื–ื™ื”ื•ื™ ื•ืฉืœื™ื˜ื” ื‘ืฉื›ื•ื ื” ืžืจืฉืชื•ืช ืกืคืงื™ื ื‘ืืžืฆืขื•ืช MAC:

/ip neighbor discovery-settings set discover-interface-list=!WAN
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN

1.5. ืื ื• ื™ื•ืฆืจื™ื ืืช ื”ืกื˜ ื”ืžื™ื ื™ืžืœื™ ื”ืžืกืคื™ืง ืฉืœ ื›ืœืœื™ ืกื™ื ื•ืŸ ื—ื•ืžืช ืืฉ ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื”ื ืชื‘:

/ip firewall filter add action=accept chain=input comment="Related Established Untracked Allow" 
connection-state=established,related,untracked

(ื”ื›ืœืœ ืžืกืคืง ื”ืจืฉืื” ืœื—ื™ื‘ื•ืจื™ื ืฉื ื•ืฆืจื• ื•ืงืฉื•ืจื™ื ืฉื™ื•ื–ืžื• ื”ืŸ ืžื”ืจืฉืชื•ืช ื”ืžื—ื•ื‘ืจื•ืช ื•ื”ืŸ ืžื”ื ืชื‘ ืขืฆืžื•)

/ip firewall filter add action=accept chain=input comment="ICMP from ALL" protocol=icmp

(ืคื™ื ื’ ื•ืœื ืจืง ืคื™ื ื’. ื›ืœ icmp ืžื•ืชืจ ืœื”ื™ื›ื ืก. ืฉื™ืžื•ืฉื™ ืžืื•ื“ ืœืžืฆื™ืืช ื‘ืขื™ื•ืช MTU)

/ip firewall filter add action=drop chain=input comment="All other WAN Drop" in-interface-list=WAN

(ื”ื›ืœืœ ืฉืกื•ื’ืจ ืืช ืฉืจืฉืจืช ื”ืงืœื˜ ืื•ืกืจ ื›ืœ ื“ื‘ืจ ืื—ืจ ืฉืžื’ื™ืข ืžื”ืื™ื ื˜ืจื ื˜)

/ip firewall filter add action=accept chain=forward 
comment="Established, Related, Untracked allow" 
connection-state=established,related,untracked

(ื”ื›ืœืœ ืžืืคืฉืจ ื—ื™ื‘ื•ืจื™ื ืžื‘ื•ืกืกื™ื ื•ืงืฉื•ืจื™ื ืฉืขื•ื‘ืจื™ื ื“ืจืš ื”ื ืชื‘)

/ip firewall filter add action=drop chain=forward comment="Invalid drop" connection-state=invalid

(ื”ื›ืœืœ ืžืืคืก ื—ื™ื‘ื•ืจื™ื ืขื connection-state=invalid ืขื•ื‘ืจ ื“ืจืš ื”ื ืชื‘. ืžื•ืžืœืฅ ื‘ื—ื•ื ืขืœ ื™ื“ื™ Mikrotik, ืืš ื‘ืžืฆื‘ื™ื ื ื“ื™ืจื™ื ืžืกื•ื™ืžื™ื ื”ื•ื ื™ื›ื•ืœ ืœื—ืกื•ื ืชืขื‘ื•ืจื” ืฉื™ืžื•ืฉื™ืช)

/ip firewall filter add action=drop chain=forward comment="Drop all from WAN not DSTNATed"  
connection-nat-state=!dstnat connection-state=new in-interface-list=WAN

(ื”ื›ืœืœ ืื•ืกืจ ืขืœ ืžื ื•ืช ืฉืžื’ื™ืขื•ืช ืžื”ืื™ื ื˜ืจื ื˜ ื•ืœื ืขื‘ืจื• ืืช ื”ืœื™ืš dstnat ืœืขื‘ื•ืจ ื“ืจืš ื”ื ืชื‘. ื–ื” ื™ื’ืŸ ืขืœ ืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช ืžืคื ื™ ืคื•ืœืฉื™ื, ืืฉืจ ื‘ื”ื™ื•ืชื ื‘ืื•ืชื• ืชื—ื•ื ืฉื™ื“ื•ืจ ืขื ื”ืจืฉืชื•ืช ื”ื—ื™ืฆื•ื ื™ื•ืช ืฉืœื ื•, ื™ืจืฉืžื• ืืช ื”-IP ื”ื—ื™ืฆื•ื ื™ ืฉืœื ื• ื›- ืฉืขืจ ื•ื‘ื›ืš ืœื ืกื•ืช "ืœื—ืงื•ืจ" ืืช ื”ืจืฉืชื•ืช ื”ืžืงื•ืžื™ื•ืช ืฉืœื ื•.)

REMARK. ื ื ื™ื— ืฉื”ืจืฉืชื•ืช LAN1 ื•-LAN2 ืžื”ื™ืžื ื•ืช ื•ื”ืชืขื‘ื•ืจื” ื‘ื™ื ื™ื”ืŸ ื•ืžื”ืŸ ืื™ื ื” ืžืกื•ื ื ืช.

1.6. ืฆื•ืจ ืจืฉื™ืžื” ืขื ืจืฉื™ืžื” ืฉืœ ืจืฉืชื•ืช ืฉืื™ื ืŸ ื ื™ืชื ื•ืช ืœื ื™ืชื•ื‘:

/ip firewall address-list
add address=0.0.0.0/8 comment=""This" Network" list=BOGONS
add address=10.0.0.0/8 comment="Private-Use Networks" list=BOGONS
add address=100.64.0.0/10 comment="Shared Address Space. RFC 6598" list=BOGONS
add address=127.0.0.0/8 comment=Loopback list=BOGONS
add address=169.254.0.0/16 comment="Link Local" list=BOGONS
add address=172.16.0.0/12 comment="Private-Use Networks" list=BOGONS
add address=192.0.0.0/24 comment="IETF Protocol Assignments" list=BOGONS
add address=192.0.2.0/24 comment=TEST-NET-1 list=BOGONS
add address=192.168.0.0/16 comment="Private-Use Networks" list=BOGONS
add address=198.18.0.0/15 comment="Network Interconnect Device Benchmark Testing"
 list=BOGONS
add address=198.51.100.0/24 comment=TEST-NET-2 list=BOGONS
add address=203.0.113.0/24 comment=TEST-NET-3 list=BOGONS
add address=224.0.0.0/4 comment=Multicast list=BOGONS
add address=192.88.99.0/24 comment="6to4 Relay Anycast" list=BOGONS
add address=240.0.0.0/4 comment="Reserved for Future Use" list=BOGONS
add address=255.255.255.255 comment="Limited Broadcast" list=BOGONS

(ื–ื•ื”ื™ ืจืฉื™ืžื” ืฉืœ ื›ืชื•ื‘ื•ืช ื•ืจืฉืชื•ืช ืฉืื™ื ืŸ ื ื™ืชื ื•ืช ืœื ื™ืชื•ื‘ ืœืื™ื ื˜ืจื ื˜ ื•ื™ืขืงื•ื‘ ืื—ืจื™ื”ื ื‘ื”ืชืื.)

REMARK. ื”ืจืฉื™ืžื” ื ืชื•ื ื” ืœืฉื™ื ื•ื™ื™ื, ืœื›ืŸ ืื ื™ ืžืžืœื™ืฅ ืœืš ืœื‘ื“ื•ืง ืžืขืช ืœืขืช ืืช ื”ืจืœื•ื•ื ื˜ื™ื•ืช.

1.7. ื”ื’ื“ืจ DNS ืขื‘ื•ืจ ื”ื ืชื‘ ืขืฆืžื•:

/ip dns set servers=1.1.1.1,8.8.8.8

REMARK. ื‘ื’ืจืกื” ื”ื ื•ื›ื—ื™ืช ืฉืœ ROS, ืฉืจืชื™ื ื“ื™ื ืžื™ื™ื ืžืงื‘ืœื™ื ืขื“ื™ืคื•ืช ืขืœ ืคื ื™ ืฉืจืชื™ื ืกื˜ื˜ื™ื™ื. ื‘ืงืฉืช ื”ื—ืœื˜ืช ื”ืฉื ื ืฉืœื—ืช ืœืฉืจืช ื”ืจืืฉื•ืŸ ืœืคื™ ื”ืกื“ืจ ื‘ืจืฉื™ืžื”. ื”ืžืขื‘ืจ ืœืฉืจืช ื”ื‘ื ืžืชื‘ืฆืข ื›ืืฉืจ ื”ืฉืจืช ื”ื ื•ื›ื—ื™ ืื™ื ื• ื–ืžื™ืŸ. ืคืกืง ื”ื–ืžืŸ ื’ื“ื•ืœ - ื™ื•ืชืจ ืž-5 ืฉื ื™ื•ืช. ื—ื–ืจื” ื—ื–ืจื”, ื›ืืฉืจ "ื”ืฉืจืช ืฉื ืคืœ" ืžืชื—ื“ืฉ, ืื™ื ื” ืžืชืจื—ืฉืช ืื•ื˜ื•ืžื˜ื™ืช. ื‘ื”ืชื—ืฉื‘ ื‘ืืœื’ื•ืจื™ืชื ื–ื” ื•ื‘ื ื•ื›ื—ื•ืช ืฉืœ multivan, ื”ืžื—ื‘ืจ ืžืžืœื™ืฅ ืœื ืœื”ืฉืชืžืฉ ื‘ืฉืจืชื™ื ืฉืกื•ืคืงื• ืขืœ ื™ื“ื™ ืกืคืงื™ื.

1.8. ื”ื’ื“ืจ ืจืฉืช ืžืงื•ืžื™ืช.
1.8.1. ืื ื• ืžื’ื“ื™ืจื™ื ื›ืชื•ื‘ื•ืช IP ืกื˜ื˜ื™ื•ืช ื‘ืžืžืฉืงื™ LAN:

/ip address add interface=ether4 address=192.168.88.254/24 comment="LAN1 IP"
/ip address add interface=ether5 address=172.16.1.0/23 comment="LAN2 IP"

1.8.2. ืื ื• ืงื•ื‘ืขื™ื ืืช ื”ื›ืœืœื™ื ืœืžืกืœื•ืœื™ื ืœืจืฉืชื•ืช ื”ืžืงื•ืžื™ื•ืช ืฉืœื ื• ื“ืจืš ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ ื”ืจืืฉื™ืช:

/ip route rule add dst-address=192.168.88.0/24 table=main comment=โ€to LAN1โ€
/ip route rule add dst-address=172.16.0.0/23 table=main comment="to LAN2"

REMARK. ื–ื•ื”ื™ ืื—ืช ื”ื“ืจื›ื™ื ื”ืžื”ื™ืจื•ืช ื•ื”ืงืœื•ืช ืœื’ืฉืช ืœื›ืชื•ื‘ื•ืช LAN ืขื ืžืงื•ืจื•ืช ืฉืœ ื›ืชื•ื‘ื•ืช IP ื—ื™ืฆื•ื ื™ื•ืช ืฉืœ ืžืžืฉืงื™ ื ืชื‘ ืฉืื™ื ื ืขื•ื‘ืจื™ื ื‘ืžืกืœื•ืœ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ.

1.8.3. ื”ืคืขืœ NAT ืฉืœ ืกื™ื›ืช ืฉื™ืขืจ ืขื‘ื•ืจ LAN1 ื•-LAN2:

/ip firewall nat add action=src-nat chain=srcnat comment="Hairpin to LAN1" 
out-interface=ether4 src-address=192.168.88.0/24 to-addresses=192.168.88.254
/ip firewall nat add action=src-nat chain=srcnat comment="Hairpin to LAN2" 
out-interface=ether5 src-address=172.16.0.0/23 to-addresses=172.16.1.0

REMARK. ื–ื” ืžืืคืฉืจ ืœืš ืœื’ืฉืช ืœืžืฉืื‘ื™ื ืฉืœืš (dstnat) ื“ืจืš IP ื—ื™ืฆื•ื ื™ ื‘ื–ืžืŸ ืฉืืชื” ื ืžืฆื ื‘ืชื•ืš ื”ืจืฉืช.

2. ืœืžืขืฉื”, ื™ื™ืฉื•ื ื”ืžื•ืœื˜ื™ื•ื•ืืŸ ื”ื ื›ื•ืŸ ืžืื•ื“

ื›ื“ื™ ืœืคืชื•ืจ ืืช ื”ื‘ืขื™ื” ืฉืœ "ืœืขื ื•ืช ืžืื™ืคื” ืฉืืœื•", ื ืฉืชืžืฉ ื‘ืฉื ื™ ื›ืœื™ ROS: ืกื™ืžืŸ ื—ื™ื‘ื•ืจ ะธ ืกื™ืžืŸ ื ื™ืชื•ื‘. ืกื™ืžืŸ ื—ื™ื‘ื•ืจ ืžืืคืฉืจ ืœืš ืœืกืžืŸ ืืช ื”ื—ื™ื‘ื•ืจ ื”ืจืฆื•ื™ ื•ืœืื—ืจ ืžื›ืŸ ืœืขื‘ื•ื“ ืขื ืชื•ื•ื™ืช ื–ื• ื›ืชื ืื™ ืœื™ื™ืฉื•ื ืกื™ืžืŸ ื ื™ืชื•ื‘. ื•ื›ื‘ืจ ืขื ืกื™ืžืŸ ื ื™ืชื•ื‘ ืืคืฉืจื™ ืœืขื‘ื•ื“ ื‘ื• ืžืกืœื•ืœ ip ะธ ื—ื•ืงื™ ื”ืžืกืœื•ืœ. ื”ื‘ื ื• ืืช ื”ื›ืœื™ื, ืขื›ืฉื™ื• ืฆืจื™ืš ืœื”ื—ืœื™ื˜ ืื™ื–ื” ื—ื™ื‘ื•ืจื™ื ืœืกืžืŸ - ืคืขื ืื—ืช, ืื™ืคื” ื‘ื“ื™ื•ืง ืœืกืžืŸ - ืฉื ื™ื™ื.

ืขื ื”ืจืืฉื•ืŸ, ื”ื›ืœ ืคืฉื•ื˜ - ืขืœื™ื ื• ืœืกืžืŸ ืืช ื›ืœ ื”ื—ื™ื‘ื•ืจื™ื ืฉืžื’ื™ืขื™ื ืœื ืชื‘ ืžื”ืื™ื ื˜ืจื ื˜ ื“ืจืš ื”ืขืจื•ืฅ ื”ืžืชืื™ื. ื‘ืžืงืจื” ืฉืœื ื•, ืืœื• ื™ื”ื™ื• ืฉืœื•ืฉ ืชื•ื•ื™ื•ืช (ืœืคื™ ืžืกืคืจ ื”ืขืจื•ืฆื™ื): "conn_isp1", "conn_isp2" ื•-"conn_isp3".

ื”ื ื™ื•ืื ืก ืขื ื”ืฉื ื™ ื”ื•ื ืฉื”ื—ื™ื‘ื•ืจื™ื ื”ื ื›ื ืกื™ื ื™ื”ื™ื• ืžืฉื ื™ ืกื•ื’ื™ื: ืžืขื‘ืจ ื•ื›ืืœื” ืฉืžื™ื•ืขื“ื™ื ืœื ืชื‘ ืขืฆืžื•. ืžื ื’ื ื•ืŸ ืกื™ืžืŸ ื”ื—ื™ื‘ื•ืจ ืขื•ื‘ื“ ื‘ื˜ื‘ืœื” ืžึดื’ื”ึธืฆึธื”. ืฉืงื•ืœ ืืช ื”ืชื ื•ืขื” ืฉืœ ื”ื—ื‘ื™ืœื” ืขืœ ื“ื™ืื’ืจืžื” ืคืฉื•ื˜ื”, ืฉื ืขืจื›ื” ื‘ืื“ื™ื‘ื•ืช ืขืœ ื™ื“ื™ ื”ืžื•ืžื—ื™ื ืฉืœ ื”ืžืฉืื‘ mikrotik-trainings.com (ืœื ืคืจืกื•ื):

Multivan ื•ื ื™ืชื•ื‘ ืขืœ Mikrotik RouterOS

ื‘ืขืงื‘ื•ืช ื”ื—ืฆื™ื, ืื ื• ืจื•ืื™ื ืฉื”ื—ื‘ื™ืœื” ืžื’ื™ืขื” ืœ-"ืžืžืฉืง ืงืœื˜", ืขื•ื‘ืจ ื‘ืฉืจืฉืจืช"ื ื™ืชื•ื‘ ืžืจืืฉ" ื•ืจืง ืื– ื”ื•ื ืžื—ื•ืœืง ืœื˜ืจื ื–ื™ื˜ ื•ืžืงื•ืžื™ ื‘ื‘ืœื•ืง "ื”ื—ืœื˜ืช ื ื™ืชื•ื‘". ืœื›ืŸ, ื›ื“ื™ ืœื”ืจื•ื’ ืฉืชื™ ืฆื™ืคื•ืจื™ื ื‘ืžื›ื” ืื—ืช, ืื ื• ืžืฉืชืžืฉื™ื ืกื™ืžืŸ ื—ื™ื‘ื•ืจ ื‘ื˜ื‘ืœื” Mangle Pre-routing ืฉืจืฉืจืื•ืช ื ื™ืชื•ื‘ ืžืจืืฉ.

ื”ืขืจื”:. ื‘-ROS, ืชื•ื•ื™ื•ืช "ืกื™ืžืŸ ื ื™ืชื•ื‘" ืžื•ืคื™ืขื•ืช ื›"ื˜ื‘ืœื”" ื‘ืกืขื™ืฃ Ip/ืžืกืœื•ืœื™ื/ื›ืœืœื™ื, ื•ื›"ืกื™ืžืŸ ื ื™ืชื•ื‘" ื‘ืกืขื™ืคื™ื ืื—ืจื™ื. ื–ื” ืขืฉื•ื™ ืœื”ื›ื ื™ืก ืงืฆืช ื‘ืœื‘ื•ืœ ืœื”ื‘ื ื”, ืื‘ืœ, ืœืžืขืฉื”, ื–ื” ืื•ืชื• ื“ื‘ืจ, ื•ื”ื•ื ืื ืœื•ื’ื™ ืฉืœ rt_tables ื‘-iproute2 ื‘ืœื™ื ื•ืงืก.

2.1. ืื ื• ืžืกืžื ื™ื ื—ื™ื‘ื•ืจื™ื ื ื›ื ืกื™ื ืžื›ืœ ืื—ื“ ืžื”ืกืคืงื™ื:

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP1" connection-mark=no-mark in-interface=ether1  new-connection-mark=conn_isp1 passthrough=no

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP2" connection-mark=no-mark in-interface=ether2  new-connection-mark=conn_isp2 passthrough=no

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP3" connection-mark=no-mark in-interface=pppoe-isp3  new-connection-mark=conn_isp3 passthrough=no

REMARK. ื›ื“ื™ ืœื ืœืกืžืŸ ื—ื™ื‘ื•ืจื™ื ืฉื›ื‘ืจ ืžืกื•ืžื ื™ื, ืื ื™ ืžืฉืชืžืฉ ื‘-connection-mark=no-mark condition ื‘ืžืงื•ื connection-state=new ื›ื™ ืœื“ืขืชื™ ื–ื” ื ื›ื•ืŸ ื™ื•ืชืจ, ื›ืžื• ื’ื ื“ื—ื™ื™ืช ื‘ื™ื˜ื•ืœ ื—ื™ื‘ื•ืจื™ื ืœื ื—ื•ืงื™ื™ื ื‘ืžืกื ืŸ ื”ืงืœื˜.


passthrough=no - ืžื›ื™ื•ื•ืŸ ืฉื‘ืฉื™ื˜ืช ื™ื™ืฉื•ื ื–ื•, ืกื™ืžื•ืŸ ืžื—ื“ืฉ ืื™ื ื• ื ื›ืœืœ ื•ื›ื“ื™ ืœื”ืื™ืฅ, ื ื™ืชืŸ ืœื”ืคืกื™ืง ืืช ืกืคื™ืจืช ื”ื›ืœืœื™ื ืœืื—ืจ ื”ื”ืชืืžื” ื”ืจืืฉื•ื ื”.

ืฆืจื™ืš ืœื–ื›ื•ืจ ืฉืื ื—ื ื• ืขื“ื™ื™ืŸ ืœื ืžืชืขืจื‘ื™ื ื‘ืฉื•ื ืฆื•ืจื” ื‘ื ื™ืชื•ื‘. ื›ืขืช ื™ืฉ ืจืง ืฉืœื‘ื™ ื”ื›ื ื”. ื”ืฉืœื‘ ื”ื‘ื ืฉืœ ื”ื™ื™ืฉื•ื ื™ื”ื™ื” ืขื™ื‘ื•ื“ ืชืขื‘ื•ืจืช ืžืขื‘ืจ ืฉื—ื•ื–ืจืช ื“ืจืš ื”ื—ื™ื‘ื•ืจ ืฉื ื•ืฆืจ ืžื”ื™ืขื“ ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช. ื”ึธื”ึตืŸ. ืื•ืชืŸ ื—ื‘ื™ืœื•ืช ืฉ(ืจืื” ื‘ืชืจืฉื™ื) ืขื‘ืจื• ื“ืจืš ื”ื ืชื‘ ื‘ื“ืจืš:

โ€œืžืžืฉืง ืงืœื˜โ€=>โ€Preroutingโ€=>โ€ื”ื—ืœื˜ืช ื ื™ืชื•ื‘โ€=>โ€Forwardโ€=>โ€ืคื•ืกื˜ ื ื™ืชื•ื‘โ€=>โ€ืžืžืฉืง ืคืœื˜โ€ ื•ื”ื’ื™ืขื• ืœื ืžืขืŸ ืฉืœื”ื ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช.

ื—ืฉื•ื‘! ื‘-ROS ืื™ืŸ ื—ืœื•ืงื” ืœื•ื’ื™ืช ืœืžืžืฉืงื™ื ื—ื™ืฆื•ื ื™ื™ื ื•ืคื ื™ืžื™ื™ื. ืื ื ืขืงื•ื‘ ืื—ืจ ื”ื ืชื™ื‘ ืฉืœ ื—ื‘ื™ืœืช ื”ืชื’ื•ื‘ื” ืœืคื™ ื”ื“ื™ืื’ืจืžื” ืœืขื™ืœ, ื”ื™ื ืชืœืš ื‘ืื•ืชื• ื ืชื™ื‘ ืœื•ื’ื™ ื›ืžื• ื”ื‘ืงืฉื”:

โ€œืžืžืฉืง ืงืœื˜โ€=>โ€Preroutingโ€=>โ€ื”ื—ืœื˜ืช ื ื™ืชื•ื‘โ€=>โ€Forwardโ€=>โ€ืคื•ืกื˜ ื ื™ืชื•ื‘โ€=>โ€ืžืžืฉืง ืคืœื˜โ€ ืจืง ืœื‘ืงืฉื”"ืžืžืฉืง ืงืœื˜โ€ ื”ื™ื” ืžืžืฉืง ISP, ื•ืœืชืฉื•ื‘ื” - LAN

2.2. ืื ื• ืžืคื ื™ื ืืช ืชืขื‘ื•ืจืช ื”ืชื—ื‘ื•ืจื” ื”ืฆื™ื‘ื•ืจื™ืช ืœื˜ื‘ืœืื•ืช ื”ื ื™ืชื•ื‘ ื”ืžืชืื™ืžื•ืช:

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP1" connection-mark=conn_isp1 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp1 passthrough=no

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP2" connection-mark=conn_isp2 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp2 passthrough=no

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP3" connection-mark=conn_isp3 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp3 passthrough=no

ืชื’ื•ื‘ื”. in-interface-list=!WAN - ืื ื• ืขื•ื‘ื“ื™ื ืจืง ืขื ืชืขื‘ื•ืจื” ืžื”ืจืฉืช ื”ืžืงื•ืžื™ืช ื•-dst-address-type=!local ืฉืื™ืŸ ืœื” ืืช ื›ืชื•ื‘ืช ื”ื™ืขื“ ืฉืœ ื›ืชื•ื‘ืช ื”ืžืžืฉืงื™ื ืฉืœ ื”ื ืชื‘ ืขืฆืžื•.

ืื•ืชื• ื“ื‘ืจ ืœื’ื‘ื™ ืžื ื•ืช ืžืงื•ืžื™ื•ืช ืฉื”ื’ื™ืขื• ืœื ืชื‘ ื‘ื“ืจืš:

"ืžืžืฉืง ืงืœื˜"=>"ื ื™ืชื•ื‘ ืžืจืืฉ"=>"ื”ื—ืœื˜ืช ื ื™ืชื•ื‘"=>"ืงืœื˜"=>"ืชื”ืœื™ืš ืžืงื•ืžื™"

ื—ืฉื•ื‘! ื”ืชืฉื•ื‘ื” ืชืœืš ื‘ื“ืจืš ื”ื‘ืื”:

"ืชื”ืœื™ืš ืžืงื•ืžื™"=>"ื”ื—ืœื˜ืช ื ื™ืชื•ื‘"=>"ืคืœื˜"=>"ื ื™ืชื•ื‘ ืคื•ืกื˜"=>"ืžืžืฉืง ืคืœื˜"

2.3. ืื ื• ืžืคื ื™ื ืืช ื”ืชืขื‘ื•ืจื” ื”ืžืงื•ืžื™ืช ืœื˜ื‘ืœืื•ืช ื”ื ื™ืชื•ื‘ ื”ืžืชืื™ืžื•ืช:

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP1" connection-mark=conn_isp1 dst-address-type=!local 
new-routing-mark=to_isp1 passthrough=no

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP2" connection-mark=conn_isp2 dst-address-type=!local 
new-routing-mark=to_isp2 passthrough=no

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP3" connection-mark=conn_isp3 dst-address-type=!local 
new-routing-mark=to_isp3 passthrough=no

ื‘ืฉืœื‘ ื–ื”, ืžืฉื™ืžืช ื”ื”ื›ื ื” ืœืฉืœื™ื—ืช ืชื’ื•ื‘ื” ืœืขืจื•ืฅ ื”ืื™ื ื˜ืจื ื˜ ืžืžื ื• ื”ื’ื™ืขื” ื”ื‘ืงืฉื” ื™ื›ื•ืœื” ืœื”ื™ื—ืฉื‘ ื›ืคืชื•ืจื”. ื”ื›ืœ ืžืกื•ืžืŸ, ืžืชื•ื™ื’ ื•ืžื•ื›ืŸ ืœื ื™ืชื•ื‘.
ืชื•ืคืขืช "ืœื•ื•ืื™" ืžืฆื•ื™ื ืช ืฉืœ ื”ื’ื“ืจื” ื–ื• ื”ื™ื ื”ื™ื›ื•ืœืช ืœืขื‘ื•ื“ ืขื ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช DSNAT ืžืฉื ื™ ื”ืกืคืงื™ื (ISP2, ISP3) ื‘ื• ื–ืžื ื™ืช. ื‘ื›ืœืœ ืœื, ืžื›ื™ื•ื•ืŸ ืฉื‘-ISP1 ื™ืฉ ืœื ื• ื›ืชื•ื‘ืช ืœื ื ื™ืชื ืช ืœื ื™ืชื•ื‘. ื”ืฉืคืขื” ื–ื• ื—ืฉื•ื‘ื”, ืœืžืฉืœ, ืขื‘ื•ืจ ืฉืจืช ื“ื•ืืจ ืขื ืฉื ื™ MXs ืฉืžืกืชื›ืœื™ื ืขืœ ืขืจื•ืฆื™ ืื™ื ื˜ืจื ื˜ ืฉื•ื ื™ื.

ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื”ื ื™ื•ืื ืกื™ื ืฉืœ ื”ืคืขื•ืœื” ืฉืœ ืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช ืขื ื ืชื‘ื™ IP ื—ื™ืฆื•ื ื™ื™ื, ืื ื• ืžืฉืชืžืฉื™ื ื‘ืคืชืจื•ื ื•ืช ืžืคืกืงืื•ืช. 1.8.2 ื•-3.1.2.6.

ื‘ื ื•ืกืฃ, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ืขื ืกื™ืžื•ื ื™ื ื›ื“ื™ ืœืคืชื•ืจ ืืช ืกืขื™ืฃ 3 ืฉืœ ื”ื‘ืขื™ื”. ืื ื• ืžื™ื™ืฉืžื™ื ืืช ื–ื” ื›ืš:

2.4. ืื ื• ืžืคื ื™ื ืชื ื•ืขื” ืžืœืงื•ื—ื•ืช ืžืงื•ืžื™ื™ื ืžืจืฉื™ืžื•ืช ื”ื ื™ืชื•ื‘ ืœื˜ื‘ืœืื•ืช ื”ืžืชืื™ืžื•ืช:

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP1" dst-address-list=!BOGONS new-routing-mark=to_isp1 
passthrough=no src-address-list=Via_ISP1

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP2" dst-address-list=!BOGONS new-routing-mark=to_isp2 
passthrough=no src-address-list=Via_ISP2

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP3" dst-address-list=!BOGONS new-routing-mark=to_isp3 
passthrough=no src-address-list=Via_ISP3

ื›ืชื•ืฆืื” ืžื›ืš, ื–ื” ื ืจืื” ื‘ืขืจืš ื›ืš:

Multivan ื•ื ื™ืชื•ื‘ ืขืœ Mikrotik RouterOS

3. ื”ื’ื“ืจ ื—ื™ื‘ื•ืจ ืœืกืคืง ื”ืื™ื ื˜ืจื ื˜ ื•ืืคืฉืจ ื ื™ืชื•ื‘ ืžืžื•ืชื’

3.1. ื”ื’ื“ืจ ื—ื™ื‘ื•ืจ ืœ-ISP1:
3.1.1. ื”ื’ื“ืจ ื›ืชื•ื‘ืช IP ืกื˜ื˜ื™ืช:

/ip address add interface=ether1 address=100.66.66.2/30 comment="ISP1 IP"

3.1.2. ื”ื’ื“ืจ ื ื™ืชื•ื‘ ืกื˜ื˜ื™:
3.1.2.1. ื”ื•ืกืฃ ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ "ื—ื™ืจื•ื":

/ip route add comment="Emergency route" distance=254 type=blackhole

REMARK. ืžืกืœื•ืœ ื–ื” ืžืืคืฉืจ ืœืชื ื•ืขื” ืžืชื”ืœื™ื›ื™ื ืžืงื•ืžื™ื™ื ืœืขื‘ื•ืจ ืืช ืฉืœื‘ ื”ื—ืœื˜ืช ื”ืžืกืœื•ืœ, ืœืœื ืงืฉืจ ืœืžืฆื‘ ื”ืงื™ืฉื•ืจื™ื ืฉืœ ื›ืœ ืื—ื“ ืžื”ืกืคืงื™ื. ื”ื ื™ื•ืื ืก ืฉืœ ืชืขื‘ื•ืจื” ืžืงื•ืžื™ืช ื™ื•ืฆืืช ื”ื•ื ืฉื›ื“ื™ ืฉื”ื—ื‘ื™ืœื” ืชืขื‘ื•ืจ ืœืžืงื•ื ื›ืœืฉื”ื•, โ€‹โ€‹ืœื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ ื”ืจืืฉื™ืช ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ื ืชื™ื‘ ืคืขื™ืœ ืœืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ. ืื ืœื, ืื– ื”ื—ื‘ื™ืœื” ืคืฉื•ื˜ ืชื•ืฉืžื“.

ื›ื”ืจื—ื‘ืช ื›ืœื™ ืœื‘ื“ื•ืง ืฉืขืจ ืœื ื™ืชื•ื— ืžืขืžื™ืง ื™ื•ืชืจ ืฉืœ ืžืฆื‘ ื”ืขืจื•ืฅ, ืื ื™ ืžืฆื™ืข ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ืช ื”ืžืกืœื•ืœ ื”ืจืงื•ืจืกื™ื‘ื™. ืžื”ื•ืช ื”ืฉื™ื˜ื” ื”ื™ื ืฉืื ื• ืื•ืžืจื™ื ืœื ืชื‘ ืœื—ืคืฉ ื ืชื™ื‘ ืืœ ื”ืฉืขืจ ืฉืœื• ืœื ื™ืฉื™ืจื•ืช, ืืœื ื“ืจืš ืฉืขืจ ื‘ื™ื ื™ื™ื. 4.2.2.1, 4.2.2.2 ื•-4.2.2.3 ื™ื™ื‘ื—ืจื• ื›ืฉืขืจื™ "ื‘ื“ื™ืงื”" ื›ืืœื” ืขื‘ื•ืจ ISP1, ISP2 ื•-ISP3 ื‘ื”ืชืืžื”.

3.1.2.2. ืžืกืœื•ืœ ืœื›ืชื•ื‘ืช "ืื™ืžื•ืช":

/ip route add check-gateway=ping comment="For recursion via ISP1"  
distance=1 dst-address=4.2.2.1 gateway=100.66.66.1 scope=10

REMARK. ืื ื• ืžื•ืจื™ื“ื™ื ืืช ืขืจืš ื”-scope ืœื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื‘-ROS target scope ื›ื“ื™ ืœื”ืฉืชืžืฉ ื‘-4.2.2.1 ื›ืฉืขืจ ืจืงื•ืจืกื™ื‘ื™ ื‘ืขืชื™ื“. ืื ื™ ืžื“ื’ื™ืฉ: ื”ื™ืงืฃ ื”ืžืกืœื•ืœ ืœื›ืชื•ื‘ืช ื”"ืžื‘ื—ืŸ" ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืงื˜ืŸ ืื• ืฉื•ื•ื” ืœื”ื™ืงืฃ ื”ื™ืขื“ ืฉืœ ื”ืžืกืœื•ืœ ืฉื™ืชื™ื™ื—ืก ืœืžื‘ื—ืŸ.

3.1.2.3. ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืจืงื•ืจืกื™ื‘ื™ ืœืชื ื•ืขื” ืœืœื ืกื™ืžืŸ ื ื™ืชื•ื‘:

/ip route add comment="Unmarked via ISP1" distance=2 gateway=4.2.2.1

REMARK. ื”ืขืจืš distance=2 ืžืฉืžืฉ ืžื›ื™ื•ื•ืŸ ืฉ-ISP1 ืžื•ื›ืจื– ื›ื’ื™ื‘ื•ื™ ื”ืจืืฉื•ืŸ ื‘ื”ืชืื ืœืชื ืื™ ื”ืžืฉื™ืžื”.

3.1.2.4. ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืจืงื•ืจืกื™ื‘ื™ ืœืชื ื•ืขื” ืขื ืกื™ืžื•ืŸ ื ื™ืชื•ื‘ "to_isp1":

/ip route add comment="Marked via ISP1 Main" distance=1 gateway=4.2.2.1 
routing-mark=to_isp1

REMARK. ืœืžืขืฉื”, ื”ื ื” ืื ื—ื ื• ืกื•ืฃ ืกื•ืฃ ืžืชื—ื™ืœื™ื ืœื™ื”ื ื•ืช ืžืคื™ืจื•ืช ืขื‘ื•ื“ืช ื”ื”ื›ื ื” ืฉื‘ื•ืฆืขื” ื‘ืกืขื™ืฃ 2.


ื‘ืžืกืœื•ืœ ื–ื”, ื›ืœ ื”ืชืขื‘ื•ืจื” ืฉื™ืฉ ืœื” ืืช ืžืกืœื•ืœ ื”ืกื™ืžื•ืŸ "to_isp1" ืชื•ืคื ื” ืืœ ื”ืฉืขืจ ืฉืœ ื”ืกืคืง ื”ืจืืฉื•ืŸ, ืœืœื ืงืฉืจ ืœืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืคืขื™ืœ ื›ืขืช ืขื‘ื•ืจ ื”ื˜ื‘ืœื” ื”ืจืืฉื™ืช.

3.1.2.5. ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืจืงื•ืจืกื™ื‘ื™ ืจืืฉื•ืŸ ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ืžืชื•ื™ื’ืช ISP2 ื•-ISP3:

/ip route add comment="Marked via ISP2 Backup1" distance=2 gateway=4.2.2.1 
routing-mark=to_isp2
/ip route add comment="Marked via ISP3 Backup1" distance=2 gateway=4.2.2.1 
routing-mark=to_isp3

REMARK. ืžืกืœื•ืœื™ื ืืœื• ื ื—ื•ืฆื™ื, ื‘ื™ืŸ ื”ื™ืชืจ, ื›ื“ื™ ืœืฉืžื•ืจ ืชืขื‘ื•ืจื” ืžืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช ื”ื—ื‘ืจื•ืช ื‘ืจืฉื™ืžืช ื”ื›ืชื•ื‘ื•ืช "to_isp*"'

3.1.2.6. ืื ื• ืจื•ืฉืžื™ื ืืช ื”ืžืกืœื•ืœ ืขื‘ื•ืจ ื”ืชืขื‘ื•ืจื” ื”ืžืงื•ืžื™ืช ืฉืœ ื”ื ืชื‘ ืœืื™ื ื˜ืจื ื˜ ื“ืจืš ISP1:

/ip route rule add comment="From ISP1 IP to Inet" src-address=100.66.66.2 table=to_isp1

REMARK. ื‘ืฉื™ืœื•ื‘ ืขื ื”ื›ืœืœื™ื ืžืกืขื™ืฃ 1.8.2, ื”ื•ื ืžืกืคืง ื’ื™ืฉื” ืœืขืจื•ืฅ ื”ืจืฆื•ื™ ืขื ืžืงื•ืจ ื ืชื•ืŸ. ื–ื” ืงืจื™ื˜ื™ ืœื‘ื ื™ื™ืช ืžื ื”ืจื•ืช ื”ืžืฆื™ื™ื ื•ืช ืืช ื›ืชื•ื‘ืช ื”-IP ื”ืžืงื•ืžื™ืช ื‘ืฆื“ (EoIP, IP-IP, GRE). ืžื›ื™ื•ื•ืŸ ืฉื”ื›ืœืœื™ื ื‘ื—ื•ืงื™ ืžืกืœื•ืœ ip ืžื‘ื•ืฆืขื™ื ืžืœืžืขืœื” ืœืžื˜ื”, ืขื“ ืœื”ืชืืžื” ื”ืจืืฉื•ื ื” ืฉืœ ื”ืชื ืื™ื, ืื– ื›ืœืœ ื–ื” ืฆืจื™ืš ืœื”ื™ื•ืช ืื—ืจื™ ื”ื›ืœืœื™ื ืžืกืขื™ืฃ 1.8.2.

3.1.3. ืื ื• ืจื•ืฉืžื™ื ืืช ื›ืœืœ ื”-NAT ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ื™ื•ืฆืืช:

/ip firewall nat add action=src-nat chain=srcnat comment="NAT via ISP1"  
ipsec-policy=out,none out-interface=ether1 to-addresses=100.66.66.2

REMARK. NATim ื›ืœ ืžื” ืฉื™ื•ืฆื, ืœืžืขื˜ ืžื” ืฉื ื›ื ืก ืœืžื“ื™ื ื™ื•ืช IPsec. ืื ื™ ืžืฉืชื“ืœ ืœื ืœื”ืฉืชืžืฉ ื‘ืคืขื•ืœื”=ืžืกื•ื•ื” ืืœื ืื ื›ืŸ ื”ื›ืจื—ื™. ื”ื•ื ืื™ื˜ื™ ื™ื•ืชืจ ื•ืขืชื™ืจ ืžืฉืื‘ื™ื ื™ื•ืชืจ ืžืืฉืจ src-nat ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ืžื—ืฉื‘ ืืช ื›ืชื•ื‘ืช ื”-NAT ืขื‘ื•ืจ ื›ืœ ื—ื™ื‘ื•ืจ ื—ื“ืฉ.

3.1.4. ืื ื• ืฉื•ืœื—ื™ื ืœืงื•ื—ื•ืช ืžื”ืจืฉื™ืžื” ืฉืืกื•ืจ ืœื”ื ืœื’ืฉืช ื“ืจืš ืกืคืงื™ื ืื—ืจื™ื ื™ืฉื™ืจื•ืช ืืœ ื”ืฉืขืจ ืฉืœ ืกืคืง ISP1.

/ip firewall mangle add action=route chain=prerouting comment="Address List via ISP1 only" 
dst-address-list=!BOGONS passthrough=no route-dst=100.66.66.1 
src-address-list=Via_only_ISP1 place-before=0

REMARK. ืœ-action=route ื™ืฉ ืขื“ื™ืคื•ืช ื’ื‘ื•ื”ื” ื™ื•ืชืจ ื•ื”ื•ื ืžื™ื•ืฉื ืœืคื ื™ ื›ืœืœื™ ื ื™ืชื•ื‘ ืื—ืจื™ื.


place-before=0 - ืžืฆื™ื‘ ืืช ื”ื›ืœืœ ืฉืœื ื• ื‘ืžืงื•ื ื”ืจืืฉื•ืŸ ื‘ืจืฉื™ืžื”.

3.2. ื”ื’ื“ืจ ื—ื™ื‘ื•ืจ ืœ-ISP2.

ืžื›ื™ื•ื•ืŸ ืฉืกืคืง ISP2 ื ื•ืชืŸ ืœื ื• ืืช ื”ื”ื’ื“ืจื•ืช ื‘ืืžืฆืขื•ืช DHCP, ืกื‘ื™ืจ ืœื‘ืฆืข ืืช ื”ืฉื™ื ื•ื™ื™ื ื”ื“ืจื•ืฉื™ื ืขื ืกืงืจื™ืคื˜ ืฉืžืชื—ื™ืœ ื›ืืฉืจ ืœืงื•ื— DHCP ืžื•ืคืขืœ:

/ip dhcp-client
add add-default-route=no disabled=no interface=ether2 script=":if ($bound=1) do={r
    n    /ip route add check-gateway=ping comment="For recursion via ISP2" distance=1 
           dst-address=4.2.2.2/32 gateway=$"gateway-address" scope=10r
    n    /ip route add comment="Unmarked via ISP2" distance=1 gateway=4.2.2.2;r
    n    /ip route add comment="Marked via ISP2 Main" distance=1 gateway=4.2.2.2 
           routing-mark=to_isp2;r
    n    /ip route add comment="Marked via ISP1 Backup1" distance=2 gateway=4.2.2.2 
           routing-mark=to_isp1;r
    n    /ip route add comment="Marked via ISP3 Backup2" distance=3 gateway=4.2.2.2 
           routing-mark=to_isp3;r
    n    /ip firewall nat add action=src-nat chain=srcnat ipsec-policy=out,none 
           out-interface=$"interface" to-addresses=$"lease-address" comment="NAT via ISP2" 
           place-before=1;r
    n    if ([/ip route rule find comment="From ISP2 IP to Inet"] ="") do={r
    n        /ip route rule add comment="From ISP2 IP to Inet" 
               src-address=$"lease-address" table=to_isp2 r
    n    } else={r
    n       /ip route rule set [find comment="From ISP2 IP to Inet"] disabled=no 
              src-address=$"lease-address"r
    n    }      r
    n} else={r
    n   /ip firewall nat remove  [find comment="NAT via ISP2"];r
    n   /ip route remove [find comment="For recursion via ISP2"];r
    n   /ip route remove [find comment="Unmarked via ISP2"];r
    n   /ip route remove [find comment="Marked via ISP2 Main"];r
    n   /ip route remove [find comment="Marked via ISP1 Backup1"];r
    n   /ip route remove [find comment="Marked via ISP3 Backup2"];r
    n   /ip route rule set [find comment="From ISP2 IP to Inet"] disabled=yesr
    n}r
    n" use-peer-dns=no use-peer-ntp=no

ื”ืกืงืจื™ืคื˜ ืขืฆืžื• ื‘ื—ืœื•ืŸ Winbox:

Multivan ื•ื ื™ืชื•ื‘ ืขืœ Mikrotik RouterOS
REMARK. ื”ื—ืœืง ื”ืจืืฉื•ืŸ ืฉืœ ื”ืชืกืจื™ื˜ ืžื•ืคืขืœ ื›ืืฉืจ ื”ื—ื›ื™ืจื” ืžืชืงื‘ืœืช ื‘ื”ืฆืœื—ื”, ื”ืฉื ื™ - ืœืื—ืจ ืฉื—ืจื•ืจ ื”ื—ื›ื™ืจื”.ืจืื” ื”ืขืจื” 2

3.3. ื”ื’ื“ืจื ื• ื—ื™ื‘ื•ืจ ืœืกืคืง ISP3.

ืžื›ื™ื•ื•ืŸ ืฉืกืคืง ื”ื”ื’ื“ืจื•ืช ื ื•ืชืŸ ืœื ื• ื“ื™ื ืžื™ื•ืช, ืกื‘ื™ืจ ืœื‘ืฆืข ืืช ื”ืฉื™ื ื•ื™ื™ื ื”ื ื“ืจืฉื™ื ืขื ืกืงืจื™ืคื˜ื™ื ืฉืžืชื—ื™ืœื™ื ืœืื—ืจ ื”ืขืœืืช ืžืžืฉืง ppp ื•ืœืื—ืจ ื”ื ืคื™ืœื”.

3.3.1. ืจืืฉื™ืช ืื ื• ืžื’ื“ื™ืจื™ื ืืช ื”ืคืจื•ืคื™ืœ:

/ppp profile
add comment="for PPPoE to ISP3" interface-list=WAN name=isp3_client 
on-down="/ip firewall nat remove  [find comment="NAT via ISP3"];r
    n/ip route remove [find comment="For recursion via ISP3"];r
    n/ip route remove [find comment="Unmarked via ISP3"];r
    n/ip route remove [find comment="Marked via ISP3 Main"];r
    n/ip route remove [find comment="Marked via ISP1 Backup2"];r
    n/ip route remove [find comment="Marked via ISP2 Backup2"];r
    n/ip route rule set [find comment="From ISP3 IP to Inet"] disabled=yes;" 
on-up="/ip route add check-gateway=ping comment="For recursion via ISP3" distance=1 
    dst-address=4.2.2.3/32 gateway=$"remote-address" scope=10r
    n/ip route add comment="Unmarked via ISP3" distance=3 gateway=4.2.2.3;r
    n/ip route add comment="Marked via ISP3 Main" distance=1 gateway=4.2.2.3 
    routing-mark=to_isp3;r
    n/ip route add comment="Marked via ISP1 Backup2" distance=3 gateway=4.2.2.3 
    routing-mark=to_isp1;r
    n/ip route add comment="Marked via ISP2 Backup2" distance=3 gateway=4.2.2.3 
    routing-mark=to_isp2;r
    n/ip firewall mangle set [find comment="Connmark in from ISP3"] 
    in-interface=$"interface";r
    n/ip firewall nat add action=src-nat chain=srcnat ipsec-policy=out,none 
    out-interface=$"interface" to-addresses=$"local-address" comment="NAT via ISP3" 
    place-before=1;r
    nif ([/ip route rule find comment="From ISP3 IP to Inet"] ="") do={r
    n   /ip route rule add comment="From ISP3 IP to Inet" src-address=$"local-address" 
    table=to_isp3 r
    n} else={r
    n   /ip route rule set [find comment="From ISP3 IP to Inet"] disabled=no 
    src-address=$"local-address"r
    n};r
    n"

ื”ืกืงืจื™ืคื˜ ืขืฆืžื• ื‘ื—ืœื•ืŸ Winbox:

Multivan ื•ื ื™ืชื•ื‘ ืขืœ Mikrotik RouterOS
REMARK. ืžื—ืจื•ื–ืช
/ip ื—ื•ืžืช ืืฉ mangle set [find comment="Connmark in from ISP3"] in-interface=$"interface";
ืžืืคืฉืจ ืœืš ืœื˜ืคืœ ื ื›ื•ืŸ ื‘ืฉื™ื ื•ื™ ื”ืฉื ืฉืœ ื”ืžืžืฉืง, ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ืขื•ื‘ื“ ืขื ื”ืงื•ื“ ืฉืœื• ื•ืœื ืขื ืฉื ื”ืชืฆื•ื’ื”.

3.3.2. ื›ืขืช, ื‘ืืžืฆืขื•ืช ื”ืคืจื•ืคื™ืœ, ืฆื•ืจ ื—ื™ื‘ื•ืจ ppp:

/interface pppoe-client add allow=mschap2 comment="to ISP3" disabled=no 
interface=ether3 name=pppoe-isp3 password=isp3_pass profile=isp3_client user=isp3_client

ื›ื ื’ื™ืขื” ืื—ืจื•ื ื”, ื‘ื•ืื• ื ื›ื•ื•ืŸ ืืช ื”ืฉืขื•ืŸ:

/system ntp client set enabled=yes server-dns-names=0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org

ืœืžื™ ืฉืงืจื ืขื“ ื”ืกื•ืฃ

ื”ื“ืจืš ื”ืžื•ืฆืขืช ืœื™ื™ืฉื ืžื•ืœื˜ื™ื•ื•ืืŸ ื”ื™ื ื”ืขื“ืคื” ืื™ืฉื™ืช ืฉืœ ื”ืžื—ื‘ืจ ื•ืื™ื ื” ื”ื™ื—ื™ื“ื” ื”ืืคืฉืจื™ืช. ืขืจื›ืช ื”ื›ืœื™ื ืฉืœ ROS ื”ื™ื ื ืจื—ื‘ืช ื•ื’ืžื™ืฉื”, ืžื” ืฉืžืฆื“ ืื—ื“ ื’ื•ืจื ืœืงืฉื™ื™ื ืœืžืชื—ื™ืœื™ื, ื•ืžืฆื“ ืฉื ื™ ื”ืกื™ื‘ื” ืœืคื•ืคื•ืœืจื™ื•ืช ืฉืœื•. ืœืžื“, ื ืกื”, ื’ืœื” ื›ืœื™ื ื•ืคืชืจื•ื ื•ืช ื—ื“ืฉื™ื. ืœื“ื•ื’ืžื”, ื›ื™ื™ืฉื•ื ืฉืœ ื”ื™ื“ืข ื”ื ืจื›ืฉ, ื ื™ืชืŸ ืœื”ื—ืœื™ืฃ ืืช ื”ื›ืœื™ ื‘ื™ื™ืฉื•ื ื–ื” ืฉืœ ื”ืžื•ืœื˜ื™ื•ื•ืืŸ ื‘ื“ื™ืงืช ืฉืขืจ ืขื ืžืกืœื•ืœื™ื ืจืงื•ืจืกื™ื‘ื™ื™ื ืœ netwatch.

ื”ืขืจื•ืช

  1. ื‘ื“ื™ืงืช ืฉืขืจ - ืžื ื’ื ื•ืŸ ื”ืžืืคืฉืจ ืœื‘ื˜ืœ ืืช ื”ืžืกืœื•ืœ ืœืื—ืจ ืฉืชื™ ื‘ื“ื™ืงื•ืช ืœื ืžื•ืฆืœื—ื•ืช ืจืฆื•ืคื•ืช ืฉืœ ื”ืฉืขืจ ืœื–ืžื™ื ื•ืช. ื”ื‘ื“ื™ืงื” ืžืชื‘ืฆืขืช ืื—ืช ืœ-10 ืฉื ื™ื•ืช, ื‘ืชื•ืกืคืช ืคืกืง ื–ืžืŸ ื”ืชื’ื•ื‘ื”. ื‘ืกืš ื”ื›ืœ, ืชื–ืžื•ืŸ ื”ืžืขื‘ืจ ื‘ืคื•ืขืœ ื ืข ื‘ื˜ื•ื•ื— ืฉืœ 20-30 ืฉื ื™ื•ืช. ืื ืชื–ืžื•ืŸ ืžื™ืชื•ื’ ื›ื–ื” ืื™ื ื• ืžืกืคื™ืง, ื™ืฉื ื” ืืคืฉืจื•ืช ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ netwatch, ืฉื‘ื• ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ื˜ื™ื™ืžืจ ื”ื‘ื“ื™ืงื” ื‘ืื•ืคืŸ ื™ื“ื ื™. ื‘ื“ื™ืงืช ืฉืขืจ ืœื ื™ื•ืจื” ืขืœ ืื•ื‘ื“ืŸ ืžื ื•ืช ืœืกื™ืจื•ื’ื™ืŸ ื‘ืงื™ืฉื•ืจ.

    ื—ึธืฉืื•ึผื‘! ื”ืฉื‘ืชืช ืžืกืœื•ืœ ืจืืฉื™ ืชื‘ื˜ืœ ืืช ื›ืœ ืฉืืจ ื”ืžืกืœื•ืœื™ื ื”ืžืชื™ื™ื—ืกื™ื ืืœื™ื•. ืœื›ืŸ, ื›ื“ื™ ืฉื™ืฆื‘ื™ืขื• check-gateway=ping ืื™ืŸ ืฆื•ืจืš.

  2. ืงื•ืจื” ืฉืžืชืจื—ืฉ ื›ืฉืœ ื‘ืžื ื’ื ื•ืŸ DHCP, ืฉื ืจืื” ื›ืžื• ืœืงื•ื— ืชืงื•ืข ื‘ืžืฆื‘ ื—ื™ื“ื•ืฉ. ื‘ืžืงืจื” ื–ื”, ื”ื—ืœืง ื”ืฉื ื™ ืฉืœ ื”ืกืงืจื™ืคื˜ ืœื ื™ืขื‘ื•ื“, ืืš ื”ื•ื ืœื ื™ืžื ืข ืžื”ืชื ื•ืขื” ืœืœื›ืช ื‘ืฆื•ืจื” ื ื›ื•ื ื”, ืžื›ื™ื•ื•ืŸ ืฉื”ืžื“ื™ื ื” ืขื•ืงื‘ืช ืื—ืจ ื”ืžืกืœื•ืœ ื”ืจืงื•ืจืกื™ ื”ืžืชืื™ื.
  3. ECMP (Equal Cost Multi-Path) - ื‘-ROS ื ื™ืชืŸ ืœืงื‘ื•ืข ืžืกืœื•ืœ ืขื ืžืกืคืจ ืฉืขืจื™ื ื•ื‘ืื•ืชื• ืžืจื—ืง. ื‘ืžืงืจื” ื–ื”, ื”ื—ื™ื‘ื•ืจื™ื ื™ื—ื•ืœืงื• ืขืœ ืคื ื™ ืขืจื•ืฆื™ื ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชื round robin, ื‘ื™ื—ืก ืœืžืกืคืจ ื”ืฉืขืจื™ื ืฉืฆื•ื™ื ื•.

ืขืœ ื”ื“ื—ืฃ ืœื›ืชื™ื‘ืช ื”ืžืืžืจ, ืขื–ื•ืจ ื‘ืขื™ืฆื•ื‘ ื”ืžื‘ื ื” ืฉืœื• ื•ืžื™ืงื•ืžื• ืฉืœ ื”ืžื‘ื˜ืื™ื - ืชื•ื“ื” ืื™ืฉื™ืช ืœืื™ื‘ื’ื ื™ @jscar

ืžืงื•ืจ: www.habr.com